Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Stronger authentication for inbound HTTP
From: mer @ world . evansville . net (Marc Rouleau)
Date: Fri, 27 Jun 1997 09:17:13 -0500 (CDT)
To: firewalls @ greatcircle . com

I understand that one-time passwords don't work for inbound Web traffic
due to the nature of the HTTP protocol.  Do any firewall vendors support
anything stronger than basic password authentication for inbound HTTP
traffic?  With the current emphasis on intranets based on Web technology,
I would guess that this is a crying need in many companies.  One of our
clients needs outside sales people to be able to access the company
intranet securely to place orders, check inventory, status, etc., and
the client is concerned about relying on simple password authentication.

I'd love to see support for something like SecureNet-every-hour or
SecureNet-every-day AND firewall- or webserver-based password
authentication.  Coupled with browser-based SSL encryption, this seems
like a solid way to allow travellers to do intranet work.  Ideally the
SecureNet-every-so-often feature would optionally require authentication
for each outside IP address so as to reduce the ability of attackers who
have learned the user's gateway password (perhaps via shoulder-surfing)
to get in while the user is in legitimately.

Is this sensible/possible?  Does anyone support it now?  Is anything like
this in the works?

    -- Marc Rouleau

VP and Chief Technology Officer    Voice: (812) 479-1700   Fax: (812) 479-3439
World Connection Services, LLC              http://www.evansville.net


Follow-Ups:
Indexed By Date Previous: Make.Money.Fast
From: "Marcus J. Ranum" <mjr @ nfr . net>
Next: Re: Pulling out Checkpoint-1 firewalls
From: Adam Shostack <adam @ homeport . org>
Indexed By Thread Previous: Re: Make.Money.Fast
From: Geoff Mulligan <geoff @ mulligan . com>
Next: Re: Stronger authentication for inbound HTTP
From: Roger Hill <rhill @ stobyn . ml . org>

Google
 
Search Internet Search www.greatcircle.com